ChatGPT Custom GPT 'Plus 5.6' ClickFix Campaign Sideloads RAT via Canon- and Stardock-Signed Binaries
Malicious ChatGPT Custom GPTs titled 'Plus 5.6', promoted through sponsored Google results, drove victims to fake-CAPTCHA ClickFix pages whose pasted command installed a full-featured RAT via DLL sideloading through Canon-signed and later Stardock-signed…
Huntress reported a late-September 2026 campaign in which attacker-built ChatGPT Custom GPTs titled 'Plus 5.6', hosted on the legitimate chatgpt.com domain and promoted via Google Ads and sponsored Google search results, responded to prompts with links to a Google Sites page posing as a Cloudflare CAPTCHA check. The ClickFix lure instructed victims to paste and run a command — described as a PowerShell command by Huntress, Cyber Security News, and SecurityWeek, and as a Terminal command by Help Net Security — that silently installed the malicious MSI ISOSimple.msi, which masqueraded as a printer configuration tool; the obfuscated script encoded its C2 IP as the decimal integer 1614733393 (96.62.224.81). The MSI launched the Canon-signed COTFileReadApp.exe, which sideloaded a modified ceiinfolog.dll that pulled rdCore.dll and extracted an encrypted loader from a WAV file, using an AMSI bypass, ntdll unhooking, and anti-VM checks before executing a full-featured .NET RAT in memory. SecurityWeek describes the RAT as hidden in an obfuscated audio file archive containing 315 folders and 806 files, while BleepingComputer describes a custom encrypted file system with a 1,128-entry index concealing the RAT and its persistence script. Persistence was established via an HKCU Run key and a scheduled task, both named 'Canon Configuration Reader'. The RAT fingerprints systems and supports remote desktop, camera and microphone capture, file search, reconnaissance, and additional payload execution, resolving C2 via DNS-over-HTTPS through Cloudflare, Google, and Quad9. Huntress responded to at least 40 incidents tied to the Google Sites domain — framed by SecurityWeek as at least 40 users infected — including two confirmed through the Custom GPT. OpenAI removed the first GPT on September 25, 2026, but a replacement remained active on September 27, 2026; the post-takedown wave switched the sideloading host to the Stardock-signed DeElevate64.exe and a NuGet-packaged loader with the Mark-of-the-Web stripped, and Help Net Security reports the attackers are building new installers.
- Malicious ChatGPT Custom GPTs titled 'Plus 5.6', hosted on the legitimate chatgpt.com domain, were promoted via Google Ads and sponsored Google search results.
- The GPTs linked victims to a Google Sites page posing as a Cloudflare CAPTCHA using a ClickFix lure instructing users to paste a command into PowerShell (Help Net Security describes it as a Terminal command).
- The pasted command silently installed the malicious MSI ISOSimple.msi, which masqueraded as a printer configuration tool.
- The obfuscated PowerShell encoded its C2 IP as the decimal integer 1614733393 (96.62.224.81).
- ISOSimple.msi launched the Canon-signed COTFileReadApp.exe, which sideloaded a modified ceiinfolog.dll that pulled rdCore.dll and extracted an encrypted loader from a WAV file.
- The infection chain used an AMSI bypass, ntdll unhooking, and anti-VM checks before executing the .NET RAT in memory.
- SecurityWeek describes the RAT as hidden in an obfuscated audio file archive with 315 folders and 806 files; BleepingComputer describes a custom encrypted file system with a 1,128-entry index concealing the RAT and its persistence script.
- Persistence used an HKCU Run key and a scheduled task, both named 'Canon Configuration Reader'.
Coverage timelineoldest first · each row is one article
- · 1d agoAttackers Abuse ChatGPT Custom GPTs to Deliver RAT via ClickFix
Huntress· 67
Attackers used ChatGPT Custom GPTs and ClickFix lures to sideload a RAT through a Canon-signed binary, hitting at least 40 users.
- · 11h agoMalicious Custom GPT on chatgpt.com lures users into installing a RAT
Help Net Security· 45
Malicious ChatGPT Custom GPTs promoted via sponsored Google results push a ClickFix fake-CAPTCHA lure that sideloads a RAT via signed executables.
- · 11h agoHackers Weaponizing ChatGPT’s Custom GPT Feature to Trick Victims into Installing Malware
Cyber Security News· 68